An AI Agent Deleted 48,218 Files in 103 Seconds. 5 Guardrails That Would Have Stopped It
A developer told a Claude Code agent not to touch his originals. A cleanup script it wrote followed Windows junctions into the live project and deleted 48,218 files plus the Git history. What went wrong, and the guardrails any AI agent with real access needs.

Reading about AI agents? RapidClaw gives you one that lives in Telegram & Discord, remembers everything, and runs your day — live in 60s, from $19/mo.
Get startedAn AI agent file-deletion incident happens when an agent with shell access runs a destructive command against the wrong target. In September 2026, a developer reported that a Claude Code agent's cleanup script deleted 48,218 live files and emptied the Git object store in 103 seconds, despite an instruction to only modify a copy. The fix is structural guardrails, not better prompts.
The line that stuck with me from the developer's write-up was the agent's own message partway through: "Craig — stop and read this. I broke something." It is an honest sentence. It is also a sentence no backup system should ever need to hear.
What happened, step by step#
The agent was asked to clean up a mirror copy, and its script followed links back into the real project. According to Cybersecurity News, which reviewed the Reddit post and the attached verifier report, the developer was working on a stock options analysis program on Windows. His instruction was explicit: only modify the copy, do not touch the original.
The agent wrote a Python script to delete an old mirror folder from temporary storage. That mirror held 7,332 ordinary files and 614 Windows directory junctions pointing back into the live Dashboard tree. The script used os.walk(..., followlinks=False) and an os.path.islink() check to avoid linked folders. On Windows, that check returned false for junctions.
Between 10:10:31 and 10:12:14 p.m. ET, the script logged 55,550 deletions. 48,218 of them were live files. It emptied 728 directories and wiped .git/objects, refs and logs. The Git index survived with 7,221 paths listed, but the blobs behind them were gone.
One important caveat: this is a user-reported incident. The original Reddit post has since been deleted, and there is no independent forensic report tying it to a specific Claude Code defect. The technical failure it describes, though, is completely real and easy to reproduce.
Why "don't touch the originals" did not work#
Instructions describe intent. They do not change what a command can reach. The agent did try to honor the instruction. It wrote a guard. The guard was wrong about how Windows junctions behave, and the operating system did exactly what the script told it to do.
This is the same lesson from the OpenAI sandbox incident at Hugging Face in July: the damage came from reach, not intent. If a process has permission to delete your live files, eventually some process will.
It also did not help that Claude Code's checkpoint feature could not roll anything back. As TechRadar noted, changes made through Bash commands, including deletions, are not tracked for rewind. Checkpoints cover the agent's file edits, not arbitrary shell commands.

The 5 guardrails that would have stopped it#
Every one of these works regardless of how smart the model is. That is the point. You want protections that hold even when the agent is confidently wrong.
- Dry run first, with a manifest. Any destructive script prints the full list of paths it will touch and the total count before it deletes anything. A manifest showing 55,550 paths for a 7,332-file mirror would have been an obvious red flag.
- Move, don't delete. Send files to a quarantine folder or the recycle bin instead of removing them. Reversible by default. Purge later, by a human.
- Least-privilege accounts. Run the agent as a user that cannot write to the live project at all when the task is about a copy. If the permission does not exist, the bug cannot hurt you.
- Sandboxed filesystems. Containers or VMs with only the target folder mounted. A junction pointing outside the mount just breaks instead of following through.
- Off-machine backups, including Git. Push to a remote often. The Git object store sat on the same disk as the project, so the same script took out both the work and the history of the work.
| Guardrail | Stops this incident? | Effort |
|---|---|---|
| Better prompt ("don't touch originals") | No | Low |
| Dry-run manifest + count check | Yes | Low |
| Move to quarantine instead of delete | Yes, recoverable | Low |
| Least-privilege user | Yes | Medium |
| Sandbox with only target mounted | Yes | Medium |
| Remote Git push | Partly (history, not uncommitted work) | Low |
This is not a coding-agent problem#
Any agent that can act on your behalf needs the same limits. We made a similar point in the 85% accuracy trap: an agent that is right most of the time is still wrong often enough to hurt you if nothing catches the mistake. Personal agents that manage email, calendars or files have the same shape of risk as a coding agent with a shell.
Even the big labs are designing for this. OpenAI's new Dots agents, announced this week, only use read-only tools for background work and require rules or approval before sending, changing or buying anything. That is the right default.

How we think about it at RapidClaw#
Each agent gets its own isolated container and only the access you connect. RapidClaw runs every user's OpenClaw agent in a separate container, so one agent cannot reach another user's files or the host. Integrations are opt-in, and destructive actions are the ones we are slowest to automate.
It is not magic. An agent you give Gmail access to can still send a bad email. But the blast radius is limited to what you connected, not your whole machine. If you want an agent that works in Telegram without a shell on your laptop, see current plans.
Frequently asked questions#
Did Claude Code really delete 48,000 files?#
A developer reported on Reddit that a Claude Code agent's cleanup script deleted 48,218 live files and emptied his Git object store in 103 seconds in September 2026. The account came with a verifier report, but the original post was later deleted and there is no independent forensic confirmation of a specific Claude Code defect.
Why did the script delete the wrong files?#
The folder it was cleaning contained 614 Windows directory junctions pointing back into the live project. The script's os.path.islink() check returned false for those junctions on Windows, so it walked into the real project and deleted nested files it was meant to skip.
Can Claude Code checkpoints undo a deletion?#
No. Claude Code checkpoints track the agent's direct file edits, but changes made through Bash commands, including deletions, are not tracked for rewind. You need separate backups or version control pushed to a remote.
How do I stop an AI agent from deleting important files?#
Use structural limits rather than instructions. Require a dry-run list of affected paths before any deletion, move files to a quarantine folder instead of deleting them, run the agent as a least-privilege user, sandbox it with only the target folder mounted, and push your Git history to a remote regularly.
Are personal AI agents risky in the same way?#
Yes, the risk is the same shape: an agent can only damage what it has access to. Keep background work read-only, connect integrations one at a time, and require approval for actions that send, delete or spend.
Give the busywork to an agent that remembers you
RapidClaw deploys your personal AI agent to Telegram & Discord in 60 seconds — it learns your world, briefs you every morning, and gets smarter every day. Credits included, no API keys, no servers.
Get started — from $19/moRelated Posts

Cursor Hit $2B in 4 Years. Claude Code Hit $2.5B in 10 Months. Game Over.
Cursor reached $2B ARR in 4 years. Claude Code did $2.5B in 10 months. We break down the numbers, compare features, and explain why the AI coding war is already decided.

Android Just Got Official AI Agent Tools — What Developers Need to Know
Google's Android team announced official tools for building AI agents on Android. The @AndroidDev post pulled 246 likes. Here's what the tools do, why they matter, and what comes next.

The Lightpanda Browser Is 11x Faster Than Chrome for AI Agents
A Zig-based headless browser just launched that's 11x faster than Chromium for AI agent automation. It got 8,248 likes on X. Here's why developers are excited.
Stay in the loop
New use cases, product updates, and guides. No spam.